Bundled Consent
Bundled consent is when an organization groups several separate requests to use your data into a single, take-it-or-leave-it consent, so you cannot agree to some purposes while refusing others. In the cookie context, this might mean asking you to accept analytics, advertising, and functional cookies all at once rather than choosing between them. This practice is generally discouraged or not permitted under several data privacy laws, which typically expect people to have genuine, granular choice.
Bundled consent refers to a single consent request that combines multiple distinct collections, uses, or disclosures of personal data, requiring an individual to accept them together rather than granting or withholding consent for each purpose separately. In EU and UK data protection practice, this conflicts with the requirement that consent be specific and freely given, since combining purposes deprives the data subject of granular control; the ICO frames valid consent as requiring genuine choice and control, which bundling can undermine. For cookie consent management, avoiding bundling generally means separating consent by cookie category or processing purpose (for example, analytics versus advertising) so that consent for one is not conditioned on consent for another. Note that the acceptability of bundling depends on the applicable legal regime, the specific purposes involved, and evolving regulatory guidance; the evidence here reflects general principles and Australian regulator descriptions rather than a definitive cross-jurisdictional rule, and detailed treatment under specific US state laws is out of scope for this entry.
Why it matters
Bundled consent sits at the heart of what many data protection regimes consider valid, meaningful consent. Under EU and UK data protection practice, consent must be freely given and specific, and the ICO frames valid consent as requiring genuine choice and control over how personal data is used. When an organization combines several distinct purposes, for example analytics, advertising, and functional cookies, into a single take-it-or-leave-it request, it can deprive individuals of that granular control, which is precisely why consent bundling is generally discouraged or not permitted under a number of data privacy laws.
For teams managing cookie consent, bundling is a practical compliance risk because it can render the underlying consent invalid even where a banner appears to collect agreement. If a user cannot accept strictly necessary or functional processing while declining advertising, the consent obtained for the non-essential purposes may not meet the specificity and freely-given standards regulators expect in most EU and UK contexts. This matters both for the lawfulness of the processing that follows under the GDPR and for the separate question of placing or accessing information on a device.
The treatment of bundling is not uniform across jurisdictions, and the acceptability of a bundled request depends on the applicable legal regime, the specific purposes involved, and evolving regulatory guidance. Australian regulators, for instance, describe bundled consent as a single request combining several requests to collect, use, and disclose personal information, and detailed treatment under specific US state privacy laws is outside the scope of this concept. Organizations should therefore treat unbundling as a general best practice while confirming the requirements applicable to their own operating jurisdictions.
Who it's relevant to
Inside Bundled Consent
Common questions
Answers to the questions practitioners most commonly ask about Bundled Consent.

